Create a FIM Rule and add a User Specific Suppression

Follow

You can create a FIM Rule with a specific user suppression and use it to monitor other folders for invalid users. To do so, you need to:

  • Create a rule to monitor changes in all home directories.
  • Create suppressions for each user for their own home directory.

How to Create a File Integrity Rule to Monitor a Folder

To create a File Integrity Rule to monitor a folder:

1. Go to RULESETS page

2. Within the Base Rule Set section, click the New Rule button

NOTE: You can create the rule in any rule set that makes sense for your organization. This particular example uses the Base Rule Set.

C_2_new_rule_button.png

3. The Add Rule fly-in displays, select the File Integrity Rule type option

C_3_file_integrity.png

4. Click the Next: Details button to display the File Rule Details form on the next page

C_4_next_details.png

5. On the File Rule Details form, complete the following fields: 

  • Rule Name
  • Alert Title
  • Alert Description

C_6_complete_form.png

6. In the Aggregate Fields click the field to display the dropdown menu and select "User"

C_7_select_user.png

7. Click the Next: File Paths button to display the File Rules Path section

C_9_file_rule_paths.png

8. Enter the File Integrity Path and select checkbox to enable Recursive monitoring

File Rule Paths.png

9. From the Events to Monitor field, click the field to display the dropdown menu and select the “All” option

C_10_select_all.png

10. Click the Create Rule button

C_11_create_rule.png

The new rule displays within the Base Rule Set section and shows the details on the right side of the page.

Add a User Specific Suppression to a File Integrity Monitor Rule

Follow theses instructions to remove monitoring for users in their own space

1. Within the File Monitor Home Directories rule, scroll to the Suppression section

D_1_suppressions.png

2. Click the New Suppressions button to display the suppression text field

D_1-1_add_suppressions.png

3. In the text field, enter the suppression

4. Click the Add New Suppression button

D_3_add_new.png

You created a suppression to remove monitoring for users in their own space.

D_4_new_suppression.png

Was this article helpful?
0 out of 0 found this helpful
Have more questions? Submit a request

Comments

0 comments

Article is closed for comments.